Abstract:
An overlay network includes a virtual content server for representing a content provider in a virtual content network and at least a client having a membership in the virtual content network and a content path between the virtual content server and the client. Each node in the content path is also a member of the virtual content network and each link between nodes is provided by a tunnel to ensure trust and integrity at the content level.
Abstract:
A multi-staged services policer implements multiple policies, at an edge device of network, on the data traffic of a single customer. In such a multi-staged services policer, services policers in a given stage may receive information from policers in subsequent stages. This information may be used when policing in the given stage.
Abstract:
At the provider edge of a core network, an egress interface may schedule based on a class dominance model, a destination dominance model or a herein-proposed class-destination dominance model. In the latter, queues are organized into sub-divisions, where each of the subdivisions includes a subset of the queues having a per hop behavior in common and at least one of the subsets of the queues is further organized into a group of queues storing protocol data units having a common destination. Scheduling may then be performed on a destination basis first, then a per hop behavior basis. Thus providing user-awareness to a normally user-unaware class dominance scheduling model.
Abstract:
Virtual Private Network (VPN) tunnels through a backbone network operated by a service provider may be considered as a logical grouping where the VPN tunnels share certain characteristics. The forwarding of a received packet onto a particular one of these VPN tunnels may be determined through a cascade of lookup tables. According to satisfaction of classification criteria, a given received packet may be modified for special treatment within the backbone network.
Abstract:
The present invention generally relates to the acceleration of customer premises equipment based virtual private networks (CPE-VPN). To provide virtual private network service from an enterprise network to a mobile client in a secure manner apparatus and method are provided whereby VPN service is provided which allows the wireless network to use data acceleration techniques. This is accomplished by providing a VPN acceleration server that terminates VPN tunnel from the enterprise network, accelerates the data for wireless transmission then encrypts the data for transmission to the mobile client (VPN acceleration client) over an encrypted acceleration tunnel. The encrypted acceleration tunnel may use PKI encryption.